Live data from Hacker News

Equifax’s Maddening Unaccountability

nytimes.com

61–70 of 238 posts

Re: Equifax’s Maddening Unaccountability

#61
post #39

Now would be a great time to go long EFX in my opinion. The stock has been slammed while Equifax is being flogged in the court of public opinion, but I doubt this leak will have any lasting financial impact. Look at the result of the Target and Home Depot breaches: whether you like it or not, the companies are still technically the victims here and no court is going to bankrupt them for data breaches that are more an…

Did you use that strategy with United Airlines after they injured that guy when bouncing him from the flight?

There's an important difference: consumers choose to fly with UA just like they choose to walk into Chipotle and buy a burrito.

The vast majority of EFX's profits come from services that consumers (effectively) don't choose to participate in.

Re: Equifax’s Maddening Unaccountability

#63

Earlier quoted context omitted.

"The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that." Not really accurate because the exploit name, especially as generic as RCE, does not tell you how it was done. RCE can be a number of things that can be fixed in numerous ways. For example, file upload functionality with path manipulation and no file type validation may lead to RCE. This can certainly be removed w…

Fair enough. I more meant that after an attacker has achieved RCE, no amount of encryption or other practices can protect sensitive info in your database.

Encryption can't save you, but other practices can.

Specifically: if you're working with a lot of very sensitive information, you structure your application such that there are multiple layers separating that data from the outside world. In the case of Equifax, that might mean implementing the "credit score check" as an internal service exposed through the public web servers (or whatever).

Re: Equifax’s Maddening Unaccountability

#64

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

Common misconception. They actually do need your approval, it's just that that approval is buried in the mountains of legalese you sign whenever you sign up for a bank account, credit card or loan.

So, if I don't want to give them my approval, I must: not sign up for a bank account, never open a credit card, avoid getting a mortgage, buy only in cash, stop renting [0], only apply to some jobs [1], not take out student loans...

[0] Some landlords require credit approval [1] Some jobs check credit

Re: Equifax’s Maddening Unaccountability

#65

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

Common misconception. They actually do need your approval, it's just that that approval is buried in the mountains of legalese you sign whenever you sign up for a bank account, credit card or loan.

Yes, but you really have zero choice. Unless you decide that you can live without a cell phone, rental car, credit card, mortgage or bank account the rest of your life.

Re: Equifax’s Maddening Unaccountability

#66

I just read about how the hack was done. Shockingly stupidly easy! 1. They realized that Equifax uses Struts. 2. They modified struts! and 3. Equifax used the updated code on their servers. DUUUUUHHHHHH!

It is more: - Critical remote execution bug was discovered in Struts2. - The vulnerability goes public too quickly. - Hackers start scanning the Internet - Equifax is found vulnerable. - Vulnerability is exploited.

Re: Equifax’s Maddening Unaccountability

#67
post #52

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

We have all agreed. We gave permission to any company that extends credit. They give our information to these credit reporting agencies on an on-going basis, personal information, including what our payment behavior and history is. All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very sim…

If an app wanted all that just to call a cab, I’d say “fuck no”, too. (Not an Uber/Lyft user, can’t confirm.) GPS, that’s all you need, and that’s all you’ll get. If you need more, ask me directly instead of digging through my shit.

Re: Equifax’s Maddening Unaccountability

#68

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

The credit system sucks. But has anybody created a better alternative yet?

Re: Equifax’s Maddening Unaccountability

#69
post #39

Now would be a great time to go long EFX in my opinion. The stock has been slammed while Equifax is being flogged in the court of public opinion, but I doubt this leak will have any lasting financial impact. Look at the result of the Target and Home Depot breaches: whether you like it or not, the companies are still technically the victims here and no court is going to bankrupt them for data breaches that are more an…

Did you use that strategy with United Airlines after they injured that guy when bouncing him from the flight?

I did. I made bank on that one (I bought calls, but same difference.)

Re: Equifax’s Maddening Unaccountability

#70
post #11

Earlier quoted context omitted.

>but I doubt this leak will have any lasting financial impact. I am going to have to stop you there. As someone who works in the financial sector, I have quite a different view of this situation. Best case scenario (for the organization) is that it is fined directly into bankruptcy and someone like FIS acquires them for pennies on the dollar. I am still waiting for CFPB to drop a nuclear bomb over this issue. There w…

Equifax has an $18B market cap. Can you name one instance of a government imposed fine for improperly stored PII exceeding even $100M? Furthermore, do you have evidence that the PII was improperly stored, or that Equifax's security practices were lacking in any way? The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.

> The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.

If the vulnerability used turns out to be the Struts one that was announced at the beginning of the year, then the "magic" here would have been quite muggle-like: update the damn dependency. Not doing so is negligence, plain and simple.

(I agree with you, though, that EFX will almost certainly come out of this relatively unscathed.)

Post reply on HN